Security · 11h ago
'WP2Shell' Exploit Chain Targets Millions of WordPress Sites
Attackers are actively chaining two newly disclosed vulnerabilities, CVE-2026-60137 and CVE-2026-63030, to remotely take over WordPress sites. The exploit, dubbed 'WP2Shell,' was observed in the wild just three days after disclosure. This poses a significant threat to one of the largest attack surfaces on the internet.
Meridian48 take
The rapid weaponization of these flaws underscores the relentless pressure on WordPress site owners to patch immediately, yet many will remain vulnerable due to delayed updates.
Read the full reporting
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover →
Dark Reading
wordpress-exploitremote-takeover